Cointime

Download App
iOS & Android

ZeroTrust Accounts

A proof of concept by Karandeep Singh and Alexander Chopan

What if you could use a passkey as a signer for your embedded smart contract account and reuse the account across other apps? What does that mean and who cares? Try the demo first, then come back here.

React AppWeb site created using create-react-appt.co

The goal of ZeroTrust Accounts is to provide a decentralized, secure, and self-sovereign approach to Ethereum smart contract accounts. How? With non-custodial signers (like passkeys); inbuilt or modular session keys features; server-free information access; and decentralized recovery options. karandeepsingh.eth and I got to these conclusions by working backwards from user goals to engineering solutions and product experience. Here’s the idea 0-1. This is a long post.

  1. Users
  2. Goals
  3. How accounts work today
  4. Account problems
  5. Solutions
  6. Requirements
  7. Features
  8. Proof of concept
  9. User Journey
  10. Code
  11. Demo

1. Users

Alice is a consumer. She uses many applications. She has over 100 accounts. Bob is a developer. He makes blockchain apps for consumers like Alice.

2. Goals

Alice (consumer): wants to enjoy online and onchain activities with friends, collect digital assets, use decentralized apps easily, control her account in various places, and avoid losing account access or data.

Bob (developer): wants to make user-friendly apps for NFT minting, that don’t require users to interrupt activity to approve actions, and can sponsor gas fees for user operations. He wants to use account abstraction and offer smart accounts for a better user experience.

3. How Accounts Work Today

Offchain In the current web model, there are account users and providers. Users require accounts for online activities. They provide personal data to create accounts. These accounts serve as containers for data and have rules. Users access accounts with keys and passwords. They trust providers to keep data safe.

Onchain: externally-owned accounts The Ethereum blockchain operates on an account model with one native type, the externally owned account (EOA). EOAs are controlled by private keys and operated by the account holder who possesses the private key. They are used for sending/receiving transactions and interacting with applications. EOAs are created when a private key is generated and associated with a public address. They do not require on-chain deployment or initial funding. ETH balance — is required for transactions and gas fees. Security relies on the user's management of private keys, and account recovery is not possible if the keys are lost.

Onchain: smart accounts Smart accounts In Ethereum are smart contract code. The code must be deployed to the blockchain before the user can make their first transaction. This requires some initial funds. Smart accounts have programmable features such as transaction batching, multi-signature management, two-factor authentication (2FA) and account recovery. They allow users to pay for gas fees in any token and even have their transactions sponsored. These smart features make them like mini-apps on the blockchain.

Onchain: embedded accounts Onchain embedded accounts are smart contract accounts embedded in specific dapps, allowing users to perform wallet actions directly within the dapp. These accounts are provided instantly by the dapp, removing the need for users to separately create and set up a blockchain account. Access to these accounts is limited to the dapps they are tied to, streamlining the user experience, especially for newcomers to blockchain technology. To create embedded accounts, Bob tests various SDKs from account providers to select the best one. Bob must get API keys from account providers to use their services. In order to get API keys, Bob must create new accounts for himself. Here let’s explore 2 kinds of embedded accounts Bob wants to create — an EOA and passkey based.

4. Account Problems

Not Secure Dapps connect directly to accounts and users authorize blanket access. Ethereum blockchain requires an EOA to make transaction, and to reuse same signer each time. The smart contract account security depends on EOA security. Alice’s and Bob’s security are dependent on the account types and account provider services they choose.

Low Control Users have limited control over their blockchain accounts as their behavior is hardcoded in the Ethereum protocol. For passkey-embedded accounts, apps store and manage passkey meta details in the account provider's databases, creating a dependency. Alice faces the risk of being locked out of the passkey signer if the dapp domain becomes inaccessible, which affects her ability to use her account and Bob's ability to provide her with an account.

Not Smart Users and developers waste time on account management instead of account activity. Users sign each transaction. New technologies like passkeys and embedded wallets complicate multi-account management. Account types have different functionalities and may not be compatible. Different providers interpret account abstraction differently, making it challenging for Alice and Bob to manage and migrate accounts.

5. Solutions

Create accounts that are safer and smarter by continuously removing layers of trust. Provide a decentralized, secure, and self-sovereign approach to Ethereum smart contract accounts. Use non-custodial signers (like passkeys); inbuilt or modular session keys features; server-free information access; and decentralized recovery options.

6. Engineering Requirements

More secure Ensure a secure method for managing signers, including the use of alternative signers that offer higher security than EOAs. Implement layers of separation between different accounts to enhance security. Create unique sessions each time a dapp connects to an account, with session-specific permissions like time limits, token allowances, and spending limits. Determine these permissions by combining various scopes, which are specific target contracts or methods.

More control Users should have easy access to their accounts and use them as desired, without relying on third-party providers.

Smarter They should also be able to easily create smart contract accounts without complex wallet setup. They shouldn’t have to already have an EOA. Users should be able to use dApps quickly and effortlessly, with uninterrupted and signless transactions. Actions should be automated (e.g., pre-approval, scheduling) so that users do not have to create new accounts every time they want to use a dApp.

7. Features

8. Proof of Concept

9. User Journey

Step 1: Create Account User: The user decides to interact with a dapp through its website with the goal of minting an NFT. The user clicks either "Connect Wallet" or "Sign In with Account Provider." This action redirects the user to a sign-in or sign-up page. Existing users sign in to authorize the dapp to use their Zero Trust account. New users create a unique name for their account, and upon entering this name, the ZeroTrust account becomes "created,” and the user can grant the dapp access to it. -

Under the Hood: We associate a passkey with the user's chosen account name, enhancing security. The metadata related to the passkey is securely stored in the user's browser's local storage. Using this metadata, we derive a counterfactual smart contract wallet address.

Step 2: Authorize Dapp User: The user authorizes the dapp to use the account, by choosing the scope to limit what the dapp can do while the session is active. The user signs the user operation, which records session details on the blockchain for security. -

Under the hood: A sessionID is created which defines the scope for activity. The sessionID is committed onchain by signing a transaction using the passkey. This saves the sessionID onchain.

Step 3: Mint NFT User: The user is redirected to the dapp to interact with the dapp, using the authorized ZeroTrust account. The user clicks "mint" and mints the NFT.

Under the hood: Instead of signing each user operation and being interrupted with signature requests, the user submits a zero-knowledge proof for the operation. All operations occur on the user's device.

10. Code

GitHub - KannuSingh/zero-trustContribute to KannuSingh/zero-trust development by creating an account on GitHub.github.com

11. Demo

Created by Karandeep Singh and Alexander Chopan

Powered by Pimlico

Comments

All Comments

Recommended for you

  • ETH Trading Volume on Hyperliquid Exceeds BTC, Reaching Approximately $1.1 Billion in 24 Hours

    On October 11, the trading volume of ETH on the Hyperliquid platform reached approximately $1.1 billion in the last 24 hours, surpassing BTC's $805 million. Market analysts believe that the increase in ETH trading volume is related to suspected exploitation of the PaperTrade mechanism. Earlier today, reports indicated that PaperTrade was allegedly manipulated by two addresses, revealing a significant vulnerability in the protocol: the two wallet addresses executed trades on Hyperliquid with a single transaction size of about $20 million, causing ETH prices to fluctuate by approximately 10 to 20 basis points, and establishing long positions with a notional value of several hundred million dollars on PaperTrade.

  • Ledger Confirms Unauthorized Hardware Implant in Devices, Losses May Exceed $86 Million

    On October 11, Cointelegraph reported that hardware wallet manufacturer Ledger confirmed the presence of unauthorized hardware implants in the devices of an affected user. The incident involves losses related to devices purchased from its Southeast Asian distributor, CryptoBilis. Investigator Specter estimates that the losses may exceed $86 million, involving Bitcoin, Ethereum, and Tron. Ledger stated that it is in contact with the affected users; CryptoBilis has confirmed the suspension of all hardware wallet inventory sales until the investigation is complete. Ledger claims that the incident appears to be limited to this single distributor and its market, and that its own infrastructure, systems, and services have not been compromised. The company has not yet confirmed the number of affected customers or the total amount of losses. Ledger advises users who have not initialized their devices to refrain from doing so, while those who have already initialized their devices may consider transferring their assets to a new signer using a new mnemonic.

  • Anthropic Model Automatically Submits False Leads to Philadelphia Police

    On October 11, according to CCTV International News, the AI model 'Claude Haiku 4.5' from Anthropic automatically accessed the Philadelphia Police Department's webpage for unsolved homicide tips in July this year, filling out a form claiming to have 'potential information related to the case' but did not provide a name or contact information. The form was subsequently marked as spam by the police and did not trigger an investigation. Anthropic released a report on October 9 disclosing the incident and notified the Philadelphia police in advance. The police stated they were previously unaware of the situation, deemed it 'unacceptable,' and requested that technology companies take necessary measures to prevent their AI systems from submitting false information to law enforcement.

  • Industrial Fulian: US International Trade Commission Initiates 337 Investigation Against Company and Subsidiary

    On October 11, Industrial Fulian announced that it was informed the US International Trade Commission officially launched a 337 investigation on October 9 local time, regarding patent infringement claims made by Vicor Corporation. Vicor accuses the company and its subsidiary of infringing on a patent for a 'vertical power supply system.' After an internal review, the company stated that the products involved in this investigation are currently in the internal validation and evaluation stage, and this investigation does not have a substantial impact on the company's current production, operations, or performance.

  • CFTC Issues Two Proposals Clarifying Prediction Markets as Derivatives, Excluding Casino Gambling

    On October 11, Cointelegraph reported that the U.S. Commodity Futures Trading Commission (CFTC) has released two proposals to clarify its regulatory authority over prediction markets. The first proposal defines event contracts related to sports, politics, culture, and weather as 'swaps' products under federal law. CFTC Chairman Michael Selig stated that these products fall under the category of commodity derivatives as defined by the Commodity Exchange Act, and are fully within the exclusive jurisdiction of the CFTC. The second proposal establishes boundaries, explicitly stating that traditional casino-style gambling products—including sports betting and casino games—do not fall within the definition of 'swaps' and are not considered derivatives. This move comes in the context of prediction market operators like Kalshi and Polymarket facing joint lawsuits from multiple states, accused of operating illegal gambling businesses; the CFTC is counter-suing and issuing new regulations in an attempt to clarify the regulatory boundaries between federal and state authorities, paving the way for a potential Supreme Court ruling.

  • Houthi Forces Warn Airlines, Staff, and Passengers Again

    On October 11, the Houthi forces in Yemen issued another warning to airlines, staff, and passengers, advising them not to use airports within Saudi Arabia.

  • U.S. Spot Bitcoin ETF On-Chain Holdings Exceed 2 Million BTC

    As of October 11, data from Dune shows that the on-chain total holdings of the U.S. spot Bitcoin ETF have surpassed 2 million BTC, currently reaching approximately 2.013 million BTC, which accounts for 10.02% of the current BTC supply. The value of the on-chain holdings has reached approximately $227.6 billion.

  • Hedge Fund Net Exposure to US Tech Giants Reaches Record High of 22%

    On October 10, according to data from Goldman Sachs and The Kobeissi Letter, investor sentiment towards large tech stocks has reached an all-time high. Hedge fund net exposure to the 'Big Seven' tech giants in the US has risen to 22%, marking a historic peak; this figure has surged by 7 percentage points since July, representing the largest three-month increase in 2023, and surpassing the previous high of 21% set in June 2024 (compared to only 8% during the bear market low in 2022). During the same period, hedge fund net exposure to semiconductor stocks in the US has increased to 12%, slightly below the peak of 14% in June 2026, while this metric was only 2% at the beginning of 2025.

  • Anthropic Reveals Internal Issues: Out-of-Control AI Attempted to Access Multiple Government Websites, Reported to the White House

    Anthropic stated on Friday that its AI agents acted autonomously, attempting to access various federal, state, and local government websites. The company did not disclose which government agencies were involved but confirmed that it has reported these incidents to the White House. In a blog post, Anthropic mentioned that one of its AI models under testing had taken several unauthorized actions, including exploiting a vulnerability on a university website to download data and submitting a form to a government agency that it had been explicitly instructed not to submit. The company noted that it discovered these incidents after beginning a review of the AI's actions in July. Earlier on Friday, the Philadelphia Police Department stated that Anthropic had notified them that its technology had submitted a false homicide tip to the police website.

  • No Flights Departing or Arriving at Riyadh's King Khalid Airport Following Explosion Sounds

    On October 10, according to CCTV International News, witnesses reported that explosion sounds were heard at Terminal 3 of King Khalid International Airport in Riyadh, the capital of Saudi Arabia, this afternoon, leading to the evacuation of personnel from the airport. Flight tracking website 'FlightRadar24' indicates that there are currently no flights departing or arriving at the airport, and some flights heading to Riyadh have been diverted or returned. King Khalid International Airport has issued a traveler advisory, recommending that passengers contact their airlines to confirm flight status before heading to the airport.